SY0-701 exam dumps

SY0-701 practice question 142 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 142

Single answerConfiguration enforcement

A security administrator discovers that several Windows laptops used by remote employees have disabled host-based firewalls and inconsistent password policies, even though the organization has documented secure configuration standards. The company wants a solution that will automatically apply the approved baseline, detect drift from that baseline, and provide centralized enforcement whenever devices reconnect to the corporate environment. Which solution BEST addresses this requirement?

  1. A

    Deploy Group Policy Objects (GPOs) through Active Directory to enforce the approved security configuration baseline

  2. B

    Run periodic vulnerability scans and email the results to system owners for manual remediation

  3. C

    Install a network intrusion detection system (NIDS) to identify laptops with incorrect local configurations

  4. D

    Require users to sign an acceptable use policy acknowledging the required security settings

Show answer and explanation

Correct answer: A

Explanation

The key phrase in this scenario is the need to automatically apply an approved baseline, detect configuration drift, and centrally enforce settings when devices reconnect. In Windows enterprise environments, GPOs are one of the most common and effective technical controls for configuration enforcement. They support secure baseline management aligned with common best practices such as those published by Microsoft Security Baselines, the Center for Internet Security (CIS) Benchmarks, and NIST guidance including NIST SP 800-128 for security-focused configuration management. Vulnerability scanning and policy documentation are helpful supporting controls, but they are not enforcement mechanisms. IDS solutions provide visibility, not baseline application. For Security+, candidates should recognize that configuration enforcement requires a technical control that can consistently push and maintain approved settings across managed systems.

  • A. Correct.

    Correct. Group Policy Objects (GPOs) in an Active Directory environment are a standard configuration enforcement mechanism for Windows systems. They can centrally apply and reapply password policies, firewall settings, and many other security baselines whenever devices authenticate to the domain or refresh policy. This directly supports configuration enforcement and drift correction rather than relying on users or manual follow-up.

  • B. Incorrect.

    Incorrect. Vulnerability scans are useful for identifying misconfigurations and missing patches, but they do not enforce settings by themselves. Emailing scan results to system owners introduces delays and depends on manual remediation, which does not meet the requirement for automatic application and centralized enforcement.

  • C. Incorrect.

    Incorrect. A NIDS monitors network traffic for suspicious activity or policy violations, but it does not directly enforce host configuration settings such as local firewall state or password policy. This option reflects a common misconception that detection tools can replace endpoint configuration management.

  • D. Incorrect.

    Incorrect. Acceptable use policies are administrative controls that help define expectations and accountability, but they do not technically enforce configurations. User acknowledgment may support governance, but it does not automatically apply or restore secure settings on managed devices.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam